Case Study
Assessing the security of mission-critical systems in the cloud
coalfire.com | 877.224.8077 | info@coalfire.com CLIENT CHALLENGE The goal of the migration was to provide significant flexibility while meeting the department’s stringent requirements for high availability of data and applications. To assure the highest level of security was met, Virtustream selected Coalfire, a leading FedRAMP Third Party Assessment Organization (3PAO), as the assessor for this DOI FedRAMP Agency Authority to Operate (ATO). Through the course of the relationship, Virtustream identified a need to upgrade from the FedRAMP Agency ATO to the FedRamp Joint Authorization Board (JAB) Provisional ATO (P-ATO). APPROACH With the NIST Special Publication 800-53 Revision 3 (FedRAMP v1) as a guide, Coalfire used recent versions of documentation (system security plan [SSP]